Apache OFBiz
cpe:2.3:a:apache:ofbiz:*:*:*:*:*:*:*, +1 more
- < 24.09.06
A vulnerability in Apache OFBiz prior to version 24.09.06 allows for improper neutralization of input during web page generation, leading to cross-site scripting (XSS). Additionally, the vulnerability includes improper limitation of pathname to a restricted directory, allowing path traversal, and improper control of code generation, resulting in code injection. Exploitation of this vulnerability could lead to arbitrary file writing, stored XSS, and remote code execution in the Catalog Manager.
Exploitation of this vulnerability could result in arbitrary file writing, stored cross-site scripting, and remote code execution in the Catalog Manager.
Users are advised to upgrade to Apache OFBiz version 24.09.06 or later, which addresses this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.